Vulnerability Description
An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain client-supplied command parameters. The issue affects find, update, delete, and aggregate commands in non-apiStrict configurations.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongodb | >= 7.0.0, < 7.0.39 |
Related Weaknesses (CWE)
References
- https://jira.mongodb.org/browse/SERVER-128433Vendor AdvisoryIssue Tracking
FAQ
What is CVE-2026-13059?
CVE-2026-13059 is a vulnerability with a CVSS score of 8.1 (HIGH). An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain cl...
How severe is CVE-2026-13059?
CVE-2026-13059 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-13059?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Mongodb.